← Back to Home

Privacy Policy

Last Updated: September 25, 2026

1. Data Collection & Security

We never store anything that identifies you. When you paste your JSON/API data into our analyzer, it is processed in real time to generate your insight and your raw filing is not kept (except briefly, de-identified and encrypted, to deliver a report you pay for — see below). By default we retain only de-identified case milestones — status codes and dates, your form type, and your service center — to power the community timeline benchmarks everyone relies on. In that community data your receipt number is kept only as a keyed one-way hash and its 8-character block prefix (Section 2 explains every place your receipt number is used), and sensitive identifiers — your Alien Registration Number (A-Number), applicant name, and mailing address — are never written to our database. You can opt out and delete your contribution at any time (see Section 5).

Saved analyses — so you can return to your results. When you purchase an analysis, we save the analysis we generate for you (not your raw filing) so you can reopen your results later without re-pasting everything — for example, from the link in your receipt email. This saved copy is tied to your purchase, retrievable only through a private, non-guessable link, automatically deleted after 90 days, and you can delete it yourself at any time from the results screen (or by contacting us). We minimize what it contains and never include your A-Number or applicant name.

Delivering a report you pay for. When you start a checkout, we hold the case data you are paying to have analyzed so we can deliver your report even if your browser loses it (for example in an in-app browser, or if you finish on another device). Before storing it we remove personal details — names, dates of birth, addresses, contact details, A-Numbers, your representative's name, and the names of files you uploaded — and we encrypt what remains with a key that is not kept in our database. It is deleted as soon as your report is ready, and within 24 hours if the checkout is not completed.

2. Your USCIS Receipt Number

USCIS considers your receipt number (for example, IOE0912345678) personally identifiable information, and so do we. This section explains how we use it to get your case status, where it is kept, and how we protect it.

How we use it

  • To get your case status. We use your receipt number to build the links to your own case on my.uscis.gov, which open in your browser while you are signed in to your own USCIS account. When you use our official USCIS Case Status API lookup, our server sends the receipt number you enter to USCIS over an encrypted connection, only to retrieve that case's current status and show it to you. We look up a receipt number only when you ask us to, and only the ones you give us.
  • To write your report. We read the case data you give us (pasted, or sent by our iPhone Shortcut or Chrome extension), which includes your receipt number, to build your timeline and report. To write the report, that case data is processed by OpenAI as our service provider (Section 6), after your name, A-Number, address and other personal details are removed and every receipt number is replaced with a placeholder (such as IOE09123-R1), so the AI never sees your receipt number; we put the real number back into your report ourselves. The same applies to questions you ask about your case. Screenshots you upload are the one exception: the AI reads the image itself. Nothing is used to train their models.
  • To keep a purchase tied to its case. A one-time report is linked to its case by a keyed one-way hash of the receipt number, never the number itself.
  • For community timelines and alerts. Only the first 8 characters (the “receipt block”, which about 100,000 cases share) and the keyed hash are used, to compare cases filed around the same time and, for Premium members, to send alerts about activity in their block.

We never sell receipt numbers, never use them for advertising or marketing, never use them to look up a case you didn't ask about, and never share them with anyone other than the service providers that need them to deliver your report.

Where it is kept, and for how long

  • Community data: never the full number, only the keyed hash and the 8-character block prefix (Section 5).
  • Your saved report (if you buy one) shows your receipt number so you can recognize it. It opens only through a private, non-guessable link, is deleted automatically after 90 days, and you can delete it sooner.
  • Checkout hold: the case data you are paying to have analyzed is encrypted (AES-256-GCM) with a key that is not stored in our database, and deleted as soon as your report is ready, or within 24 hours if the checkout is not completed.
  • iPhone Shortcut hand-off: held for at most 10 minutes, only to pass your case data from your phone to your browser, then deleted.
  • Screenshot readings: if you upload a screenshot, the text we read from it is kept for up to 24 hours so your report can use it, then deleted.
  • USCIS Case Status API results are handled the same way as case data you paste: shown to you, and kept only as described here.
  • Your own device: the site may keep your case data in your browser's storage so you don't have to paste it again. It stays on your device.

How we protect it

  • Everything sent between your device, our servers, USCIS and our service providers is encrypted in transit (HTTPS/TLS).
  • Our database is encrypted at rest, is not publicly readable, and is reached only by our own servers using restricted credentials. Our USCIS API credentials are kept as server secrets, never in the app or your browser.
  • We do not write receipt numbers to our server logs, and the parts of our pages that show your case data are hidden from the Microsoft Clarity session recordings described in Section 6.
  • Only the people who run and support the service can access our systems, and only as needed to do so.
  • If a receipt number is ever exposed in a data breach, we will notify you as described in Section 11.

To have us delete anything tied to your receipt number, email info@casestatusapi.com. We complete requests within 30 days.

3. Account & Subscription Data

If you subscribe to our monthly plan or make a one-time purchase, we store only the following account information to manage your subscription:

  • Email address — used to identify your account and check subscription status.
  • Subscription status — whether your plan is active, canceled, or past due.
  • Stripe customer ID and subscription ID — used to link your account to Stripe for billing management.
  • Case alerts (Premium members) — if you have cases saved in My Case, we may email you, at most once a week, when other cases with the same form in your receipt block get USCIS updates. We keep a record of which alerts we sent so we don't repeat them; it is deleted with your account. Every alert has a link to stop them.

We never store your credit card details. All payment information is handled securely by Stripe. Aside from the saved analysis described in Section 1 — which you can delete at any time — your billing data and your case data are kept separate.

4. Local Storage & Cookies

We use strictly necessary cookies and local browser storage to provide core site functionality, maintain security, and prevent the abuse of promotional offers.

To improve your experience, we use your browser's Local Storage to remember your email for subscription status checks and to prevent repeated promotional discount popups once claimed. Analysis results may be temporarily stored in Session Storage on your device during your visit. This data stays on your computer and is never uploaded to us.

We also use Google Analytics and Google Tag Manager (cookies) to track anonymous usage statistics (e.g., page views) to help us improve the website.

5. Community Milestone Data & Cryptographic Anonymization

To help the broader immigration community benchmark realistic USCIS processing timelines, CaseStatusAPI contributes de-identified case milestones by default. This data carries no information that identifies you or your case, and you can opt out and delete your contribution at any time.

  • On by Default, Anonymized — Opt Out Anytime: De-identified milestones are contributed automatically so every applicant benefits from the shared benchmark. Because the data carries nothing that identifies you, it is not personal data — and you can opt out, and delete what was contributed, at any time.
  • Keyed One-Way Hashing: When contributing, your receipt number is converted into a keyed one-way hash (HMAC-SHA-256 with a secret key kept outside our database). Only its 8-character block prefix is kept readable, and full receipt numbers inside USCIS's own text are cut to that prefix too. The community data never contains a full receipt number.
  • Zero Personal Identifiers (PII): We strictly strip and discard all applicant names, Alien Registration Numbers (A-Numbers), birth dates, postal addresses, phone numbers, mail tracking numbers, and payment information.
  • Milestone-Only Telemetry: Only high-level timeline metadata (Form type, Service Center/Field Office, and milestone transition timestamps) is collected to compute community velocity metrics.
  • Revocation & Deletion: You can opt out at any time through the community tracker settings.

6. Third-Party Services

Stripe: We use Stripe for payment and subscription processing. Your payment information is handled entirely by Stripe securely; we never see or store your credit card details. See Stripe's Privacy Policy.

OpenAI: We use OpenAI's API to generate the case insights. Personal details are removed and receipt numbers are replaced with placeholders before anything is sent (Section 2). Data sent to OpenAI is subject to their enterprise privacy policies and is not used to train their models.

Supabase: We use Supabase to securely store your account and subscription information (email, subscription status) and the case data described in Sections 1, 2 and 5: de-identified community milestones, and, for your own use, the reports you buy and, for Premium members, the case history shown in My Case. Names, A-Numbers and addresses are never stored.

Microsoft Clarity: We use Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. The parts of our pages that show your case data (your receipt number, pasted responses, case details and reports) are hidden, so recordings never contain them. On every page, Clarity also hides anything you type into a form and any numbers or email addresses. By using our site, you agree that we and Microsoft can collect and use this data. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

7. Data Retention

Your subscription account data is retained as long as your account is active. If you cancel, we may keep a minimal record so you can reactivate later. We keep account data only as long as it is needed for the purposes described in this policy, and we remove or de-identify it when it is no longer needed. You can delete your account and its data yourself at any time from your Account page, or by emailing info@casestatusapi.com. Self-service deletion is immediate; email requests are completed within 30 days.

Case data held for a checkout (Section 1) is deleted once your report is ready, and within 24 hours if the checkout is not completed. Saved analyses are automatically deleted 90 days after they are created. You can delete a saved analysis immediately from the results screen, or, when signed in, delete all saved analyses tied to your account. Optional community milestone data (Section 5) is anonymized and retained to compute aggregate trends; you can opt out at any time.

8. Categories of Data We Collect (and What We Never Collect)

We practice data minimization and collect only what the service needs:

  • Account data: your email address and your subscription or purchase status.
  • Billing data: a Stripe customer and subscription ID. We never see or store your card number.
  • Receipt numbers: used and kept only as described in Section 2.
  • De-identified case milestones: your form type, service center, event codes, and status dates, plus a one-way salted hash of your receipt number. This carries nothing that identifies you.
  • Website usage data: anonymous analytics and product-improvement metrics, including page views and interaction data such as heatmaps and session replay, through Google Analytics and Microsoft Clarity.
  • Reviews you choose to leave: your star rating, any comment you write, and your report's form type. We publish a review only if you allow it, and then only with the name you choose to show (or "Verified customer"). A review is linked to your purchase only so we can mark it as verified. Reviews are optional, and we delete one when you ask.

We do not collect, and we ask you never to submit, the following:

  • Precise geolocation data.
  • Financial account information, such as bank or card numbers.
  • Medical, health, or biometric information.
  • Your device contacts, call logs, or messages.
  • Your Alien Registration Number (A-Number), full name, date of birth, phone number, or mailing address. If any of these appear in data you paste, they are stripped and never written to our database.

9. How We Share Your Data, and Your Choices

We do not sell your personal information. We have never sold it, and we do not share it for money, for advertising, or for any other company's independent use.

We share data only with the service providers that make the product work — the same providers named in Section 6 — and only so they can perform that work for us. These providers are bound by contract to protect your data, to use it only to provide their service to us, and not to disclose it or use it for their own purposes. We do not permit any third party to use or disclose your information — including de-identified, anonymized, or pseudonymized data — for any reason without your consent, except where the law requires it.

Your choices. Contributing de-identified community milestones (Section 5) is your choice. Every time you check a case, a line under your results says so, with a “Turn off” link; you can change your answer at any time there or from your Account or the Insights page. Turning it off stops future contributions from that device, and from your account if you are signed in. The Opt Out button on your Account or Insights page also deletes the timelines you contributed. The benefit of contributing is more accurate community processing-time benchmarks for everyone. Because the contribution is de-identified — no name, A-Number, or readable receipt number — the risk to you is minimal. We do not collect genetic, family-history, or relatives' information, so sharing your milestones cannot reveal anything about other people.

10. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, to access a copy of it, to ask us to correct or delete it, and to opt out of its sale or sharing. Because we do not sell or share your personal information, there is nothing for you to opt out of. We will never treat you differently for exercising these rights.

Do Not Sell or Share My Personal Information: we do not sell or share your personal information. To make any privacy request, email info@casestatusapi.com. We will respond within the time the law allows, generally 45 days.

11. Data Breach Notification

If we discover a data breach that affects your personal information, we will notify you without undue delay, consistent with applicable law. Our notice will explain what happened, what information was involved, and the steps you can take to protect yourself.

12. Closing Your Account

You can close your account at any time. From your Account page, the "Delete account" control removes your account and its data immediately and cancels any active subscription for you. You can also email info@casestatusapi.com to request deletion, which we complete within 30 days.

13. Business Transfers & Change of Ownership

If our business is sold, merged, or transferred, we will require the new owner to honor a privacy policy at least as protective as this one. We will notify you of any change of ownership before your data becomes subject to a different policy, and you may delete or export your data before the transfer takes effect.

14. Changes to This Policy

If we make a material change to this policy or to how we handle your data, we will not apply it silently. We will notify you, give you a plain-language summary of what changed, and ask for your active consent before the change takes effect for your account. Minor, non-material edits are reflected by updating the "Last Updated" date at the top of this page.

15. Contact Us

If you have any questions about this Privacy Policy or wish to request deletion of your data, please contact us at info@casestatusapi.com.

Operated by ComplyWhiz LLC.